Show filters
502 Total Results
Displaying 51-60 of 502
Sort by:
Attacker Value
Unknown

CVE-2024-34685

Disclosure Date: July 09, 2024 (last updated August 30, 2024)
Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application but it has a low impact on its confidentiality and integrity.
Attacker Value
Unknown

CVE-2024-34688

Disclosure Date: June 11, 2024 (last updated August 10, 2024)
Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact on the availability of the application.
Attacker Value
Unknown

CVE-2024-33001

Disclosure Date: June 11, 2024 (last updated August 10, 2024)
SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding the service. An impact of this Denial of Service vulnerability might be long response delays and service interruptions, thus degrading the service quality experienced by legitimate users causing high impact on availability of the application.
Attacker Value
Unknown

CVE-2024-28164

Disclosure Date: June 11, 2024 (last updated August 07, 2024)
SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the application.
Attacker Value
Unknown

CVE-2024-4939

Disclosure Date: June 05, 2024 (last updated June 12, 2024)
The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div shortcode in all versions up to, and including, 6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-30314

Disclosure Date: May 16, 2024 (last updated December 18, 2024)
Dreamweaver Desktop versions 21.3 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does require user interaction.
Attacker Value
Unknown

CVE-2024-34687

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker can control code that is executed within a user’s browser, which could result in modification, deletion of data, including accessing or deleting files, or stealing session cookies which an attacker could use to hijack a user’s session. Hence, this could have impact on Confidentiality, Integrity and Availability of the system.
0
Attacker Value
Unknown

CVE-2024-32733

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successful exploitation the attacker can access or modify sensitive information with no impact on availability of the application
0
Attacker Value
Unknown

CVE-2024-30218

Disclosure Date: April 09, 2024 (last updated September 28, 2024)
The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. This leads to a considerable impact on availability.
0
Attacker Value
Unknown

CVE-2024-27899

Disclosure Date: April 09, 2024 (last updated April 10, 2024)
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and availability.
0